[Sis-dtn] BPSec edge-case testing and protocol fuzzing

Lars Baumgaertner Lars.Baumgaertner at esa.int
Tue Jul 1 07:36:35 UTC 2025


Hi Brian,

We briefly mentioned our collaboration with Stephan Havermans (PhD Student @ IMDEA Madrid) who does fuzzing and automated interop/conformance tests. The first iteration of his work focused on BPv7 itself but BPSec is on the roadmap. Main challenge was fuzzing the protocol but not the CBOR encoder, so generated inputs should be protocol aware.

The plan was to present his approach with some results maybe at the CCSDS fall meeting - or at a regular CCSDS Thursday meeting but I guess his presentation would also be interesting for the Security WG.

I put him in CC, for more details, we can take the discussion also off-list.

Kind regards,
Lars


From: SIS-DTN <sis-dtn-bounces at mailman.ccsds.org> On Behalf Of Sipos, Brian J. via SIS-DTN
Sent: 30 June 2025 21:13
To: sis-dtn at mailman.ccsds.org
Subject: [Sis-dtn] BPSec edge-case testing and protocol fuzzing

All,
During the last CCSDS meeting, when discussing BPSec implementation and testing there was a brief mention (I think) of fuzz testing BPSec implementations. To anyone who is involved in this kind of thing, has there been work already started on this topic? And if so are there any good experiences or recommended tools to assist this?
Thanks for any pointers,
Brian S.
This message is intended only for the recipient(s) named above. It may contain proprietary information and/or protected content. Any unauthorised disclosure, use, retention or dissemination is prohibited. If you have received this e-mail in error, please notify the sender immediately. ESA applies appropriate organisational measures to protect personal data, in case of data privacy queries, please contact the ESA Data Protection Officer (dpo at esa.int).
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.ccsds.org/pipermail/sis-dtn/attachments/20250701/3131e827/attachment-0001.htm>


More information about the SIS-DTN mailing list